authentik 是一款开源的身份提供商(Identity Provider)。在版本 2026.2.7、2026.5.7 和 2026.8.2 之前,未认证的攻击者可以向部署了 authentik 且配置为身份提供商(identity-provider)角色或 SAML 源(SAML source)角色的系统中提交格式错误的 SAML 消息。此类消息可能导致处理 或 路径的 worker 进程停止响应,从而使分配给该 worker 的请求失败。 尽管 worker 进程的终止和自动重启不会导致基于数据库的会话丢
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 |
affected |
>= 2026.5.0, < 2026.5.7 |
affected | ||
>= 2026.8.0, < 2026.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goauthentik | authentik | < 2026.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94606 | 8.9 HIGH | authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage |
| CVE-2026-94609 | 8.8 HIGH | authentik: Privilege Escalation to Superuser via Group Hierarchy |
| CVE-2026-94611 | 8.1 HIGH | authentik: Stored credentials are readable with view permission alone |
| CVE-2026-94612 | 7.4 HIGH | authentik: Authentication bypass via assertion confusion in SAML sources |
No comments yet